Threat Level: green Handler on Duty: Pasquale Stirparo

SANS ISC: InfoSec Handlers Diary Blog - Unpatched Exploit: Skype for Mac OS X InfoSec Handlers Diary Blog


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

Unpatched Exploit: Skype for Mac OS X

Published: 2011-05-06
Last Updated: 2011-05-09 19:01:31 UTC
by Richard Porter (Version: 2)
4 comment(s)

--- Update:

There has been an update to Skype for Mac OS X. It is recommended that you update. Latest version seems to be 5.1.0.922. It is not clear from the Skype website as to addressing the below issue but updating is a good idea.

 

 

According to a Pure Hacking Blog Entry = http : //www.purehacking.com/blogs/gordon-maddern/skype-0day-vulnerabilitiy-discovered-by-pure-hacking and The Register UK = http : //www.theregister.co.uk/2011/05/06/skype_for_mac_critical_vulnerability/

There is a 0 Day exploit that exists for Skype on MAC. Windows and Linux are unaffected. Some best practices for Skype include setting your messages to only allow from Contacts. This does not protect you from infected contacts but it might help.

Please take measures to protect yourself. We are not aware of this being exploited in the wild and as most of us might use the operating system affected, we are both personally and professionally interested.

 

 

Richard Porter

--- ISC Handler on Duty

 

4 comment(s)
Diary Archives